CVE-2020-10755 describes an insecure-credentials flaw in OpenStack Cinder versions prior to 14.1.0, 15.2.0, and 16.1.0, specifically when using the Dell EMC ScaleIO or VxFlex OS backend storage driver. This vulnerability exposes backend storage credentials (username and password) within the connection_info element of Block Storage v3 Attachments API calls. An authenticated user can leverage this to access other users' volumes and potentially the ScaleIO/VxFlex OS Management API. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring low privileges, and resulting in high confidentiality impact without affecting integrity or availability. The EPSS score is low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are also minimal, aligning with the typical pattern for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.1.0CPE matchmatch criteria | cpe:2.3:a:redhat:openstack-cinder:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.2.0CPE matchmatch criteria | cpe:2.3:a:redhat:openstack-cinder:*:*:*:*:*:*:*:* | ||
>= 16.0.0, < 16.1.0CPE matchmatch criteria | cpe:2.3:a:redhat:openstack-cinder:*:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
20.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.